Earlier quoted context omitted.
That's the point of the Secure Enclave, where the password keys are stored. It's designed to be impossible to image. Early attacks relied on pulling the power to the chip after it sent a failure message but before it updated the attempt counter, this is fixed on newer revisions to happen the other way around.
Are you a hardware engineer at apple speaking in official capacity? Not that I would believe that even you were. Of course the government can read their surveillance device.
It's never been easier for the cops to break into your phone
21–30 of 35 posts
Re: It's never been easier for the cops to break into your phone
#22Re: It's never been easier for the cops to break into your phone
#23Don't know Apple, but Androids can be put into Bootloader and Recovery without password or pin. Most Recovery[s] give you access to the file system (if not, Bootloader can be used to install your own Recovery). Extract the files and run through whatever software you have for decryption.
Re: It's never been easier for the cops to break into your phone
#24Don't know Apple, but Androids can be put into Bootloader and Recovery without password or pin. Most Recovery[s] give you access to the file system (if not, Bootloader can be used to install your own Recovery). Extract the files and run through whatever software you have for decryption.
Re: It's never been easier for the cops to break into your phone
#25Don't know Apple, but Androids can be put into Bootloader and Recovery without password or pin. Most Recovery[s] give you access to the file system (if not, Bootloader can be used to install your own Recovery). Extract the files and run through whatever software you have for decryption.
Can you name a single Android phone or tablet model that is <10 y.o. for which you can access personal data with this method?
Obscure Chinese brands made such android phones for few more years.
All Google Pixels (2016 and later), and virtually any android phone made after circa 2018 are safe from naive bootloader attack: user data is encrypted, plus you have to "OEM unlock" to even get the recovery to run.
Re: It's never been easier for the cops to break into your phone
#26Don't know Apple, but Androids can be put into Bootloader and Recovery without password or pin. Most Recovery[s] give you access to the file system (if not, Bootloader can be used to install your own Recovery). Extract the files and run through whatever software you have for decryption.
Can you name a single Android phone or tablet model that is <10 y.o. for which you can access personal data with this method?
Re: It's never been easier for the cops to break into your phone
#27Earlier quoted context omitted.
Isn’t the Secure Enclave another separate flash chip?
Yes but with the controller built in and hardware hardening. They are designed precisely to prevent this kind of attack. I bet most of the exploits used by these boxes have nothing to do with the secure element but just bypass security using exploits in standard system or USB code. Most phones will be captured with the OS running but just the UI locked, with all encrypted volumes already mounted.
Re: It's never been easier for the cops to break into your phone
#28Earlier quoted context omitted.
Yes but with the controller built in and hardware hardening. They are designed precisely to prevent this kind of attack. I bet most of the exploits used by these boxes have nothing to do with the secure element but just bypass security using exploits in standard system or USB code. Most phones will be captured with the OS running but just the UI locked, with all encrypted volumes already mounted.
If they can access the iCloud account then the phone can be backed up remotely then read the backup.
But this is not how cellebrite boxes work anyway. They focus on the device.
Re: It's never been easier for the cops to break into your phone
#29There are numerous ways for LE to view and manipulate your online experiences. Your phone can be viewed remotely like remote desktop over your cell connection without your knowledge. Defeating all end to end encryption in the process.
LE is given access to your application APIs and can control the results you get from job searches, your YouTube recommended videos and even the advertisements you are served.
Now you may think there are protections and they need a warrant. They do not in many cases. Most important to understand is that LE only has to follow the law and the rules if they want to use information they collect against you in court. Most requests do not go this far. So it is wide open for your information.
Even getting your phone and getting into it is easier than ever. However once you get here odds are it will face scrutiny in court.
I am hopeful a lot of this will continue coming out and being verified more officially. We live in a surveillance state and most people need to be educated about it.
Re: It's never been easier for the cops to break into your phone
#30Earlier quoted context omitted.
Yes but with the controller built in and hardware hardening. They are designed precisely to prevent this kind of attack. I bet most of the exploits used by these boxes have nothing to do with the secure element but just bypass security using exploits in standard system or USB code. Most phones will be captured with the OS running but just the UI locked, with all encrypted volumes already mounted.
If they can access the iCloud account then the phone can be backed up remotely then read the backup.